Third-party assessors are independent organizations accredited by the Standards Council of Canada to evaluate defence contractors' compliance with CPCSC Level 2 requirements.
Unlike Level 1's self-assessment model, Level 2 requires external verification by independent experts to ensure objectivity and rigor. Third-party assessors conduct comprehensive evaluations of your security implementation across all 98 required controls, examining documentation, interviewing personnel, testing technical implementations, and observing operational practices.
They function similarly to financial auditors or ISO certification bodies, bringing independent expertise, following standardized assessment methodologies, maintaining objectivity and impartiality, and issuing formal assessment reports documenting findings.
The "third party" designation emphasizes their independence: you (the contractor being assessed) are the first party, the government (whose requirements you're meeting) is the second party, and the assessor is an independent third party with no stake in the outcome beyond professional reputation for conducting credible assessments.
Level 2 assessments follow rigorous procedures aligned with NIST SP 800-171A, the companion document to NIST SP 800-171 that defines assessment procedures for each security requirement.
Assessors examine the following areas during their evaluation:
The assessment typically occurs over several days or weeks depending on organization size and complexity, with both on-site and remote activities.
Once the Level 2 accreditation ecosystem matures in 2027, the Standards Council of Canada will likely maintain a public registry or directory of accredited CPCSC Level 2 certification bodies. This will be your primary resource for identifying qualified assessors.
Several resources can help you find accredited assessors:
When the ecosystem is nascent in 2027, options may be limited, but as it matures, multiple accredited certification bodies should emerge providing contractors with choices.
Not all SCC-accredited certification bodies will be identical, even though they all meet accreditation standards.
Consider several factors when selecting an assessor:
A critical rule in the certification ecosystem is that the organization conducting your formal Level 2 assessment cannot be the same organization that provided consulting services to help you achieve compliance. This independence requirement prevents conflicts of interest where an assessor might be incentivized to overlook deficiencies in systems they helped design or implement.
If you engage a consultant to help prepare for Level 2, you must use a different organization for the actual certification assessment. Some organizations offer both consulting and assessment services but maintain separate business units with information barriers between them—verify with the SCC whether such arrangements satisfy independence requirements for your specific situation.
Typical Level 2 assessments follow a multi-phase process spanning several months.
The pre-assessment phase includes:
The formal assessment phase includes:
The post-assessment phase involves:
Finally, certification issuance provides official certification documentation upon successful completion, which you then record in your CanadaBuys profile.
Level 2 assessment costs vary widely based on organizational factors. Small organizations with simple IT environments might pay in the range of $20,000-$50,000 for tri-annual assessment, while larger, more complex organizations with multiple locations, extensive IT infrastructure, and large user populations might pay $100,000 or more.
These costs cover the assessor's time for planning, conducting assessment activities, analyzing evidence, preparing reports, and managing the certification process. Travel costs may be additional if on-site assessment is required.
Organizations should obtain quotes from multiple accredited assessors and ensure quotes clearly define what's included, what's additional, and what triggers additional costs (like finding significant deficiencies requiring follow-up assessment).
To maximize value from your assessment investment and minimize the risk of deficiencies that delay certification, prepare thoroughly.
Follow these preparation steps:
The better prepared you are, the more efficiently the assessment proceeds and the higher your likelihood of certification on the first attempt without requiring expensive remediation cycles.
After initial certification, you'll maintain an ongoing relationship with your certification body or potentially switch to a different accredited body for the next tri-annual assessment. Between full assessments, you must complete annual affirmations attesting that you've maintained compliance.
Some certification bodies offer surveillance or monitoring services between full assessments to help ensure continued compliance, though these are typically optional add-on services rather than mandatory requirements.
View your certification body as a partner in maintaining security posture, not just a one-time audit vendor, and leverage their expertise to continuously improve your security program.
Additional resources are available to help you understand third-party assessments:
Preparing for CPCSC (Canadian Program for Cyber Security Certification) demands deep knowledge of the certification framework, careful evidence preparation, and hands-on technical implementation. Plurilock delivers with compliance readiness specialists serving Canadian defense suppliers who bring proven experience guiding contractors through cybersecurity certification programs on both sides of the border.
As an established CMMC readiness provider for U.S. defense contractors, we were among the first to extend that expertise north—launching CPCSC readiness services early and serving Canadian defense suppliers from the program's earliest days. We don't conduct audits; we get you ready for them, then help you stay ready.
Why we're the superior choice:
CPCSC-ready—with proven defense contractor experience guiding every step.
A plurilock representative will contact you within one business day.
Contact Plurilock
+1 (888) 776-9234 (Plurilock)